20
Configuring user group attributes
User groups simplify local user configuration and management. A user group comprises a group of local
users and has a set of local user attributes. Configure local user attributes for a user group to implement
centralized user attributes management for the local users in the group. Configurable user attributes
include password control attributes and authorization attributes.
By default, every newly added local user belongs to the system default user group system and bears all
attributes of the group. To change the user group to which a local user belongs, use
user-group
in local
user view.
To configure attributes for a user group:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Create a user group and enter user
group view.
user-group
group-name
Required.
3.
Configure
password
control
attributes for
the user
group.
Set the password
aging time.
password-control aging
aging-time
Optional.
By default, the global
setting (90 days by
default) is used.
Set the minimum
password length.
password-control length
length
Optional.
By default, the global
setting (10 characters
by default) is used.
Configure the
password
composition
policy.
password-control composition type-
number
type-number
[
type-length
type-length
]
Optional.
By default, the global
settings (both are one
by default) are used.
4.
Configure the authorization
attributes for the user group.
authorization-attribute
{
acl
acl-
number
|
callback-number
callback-number
|
idle-cut
minute
|
level
level
|
user-profile
profile-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
Optional.
By default, no
authorization attribute is
configured for a user
group.
Displaying and maintaining local users and local user groups
To do…
Command…
Remarks
Display local user information
(on a centralized router).
display local-user
[
dvpn
|
service-type
{
ftp
|
portal
|
ppp
|
ssh
|
telnet
|
terminal
|
web
}
|
state
{
active
|
block
} |
user-name
user-
name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display local user information
(on a distributed router).
display local-user
[
dvpn
|
idle-cut
{
disable
|
enable
} |
service-type
{
ftp
|
lan-access
|
portal
|
ppp
|
ssh
|
telnet
|
terminal
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
] [
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the user group
configuration information.
display user-group
[
group-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view